nezhahq has 12 CVEs on record. Disclosures have slowed: 2 in the last 90 days after 10 in the 90 before. The busiest recent month was June 2026 with 10. The median CVSS is 6.9 (medium), with 3 rated critical. None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.9
- Publish → KEV
- —
- Last 90 days
- 2 prev 10
Worst active — by depth score
CVE-2026-53519Critical· 9.1Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key63CVE-2026-62283Critical· 9.9Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool55GHSA-q6xx-5vr8-p898Critical· 9.9Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check54CVE-2026-49396High· 7.1Nezha has cross-site GET request that can trigger stored cron commands on a victim's agents39CVE-2026-48119High· 7.1Nezha's authenticated agents can forge service-monitor results for other users' services39
nezhahq vulnerabilities
CVEs affecting nezhahq, newest first. Open any entry for full detail, references, and exploit status.
12 CVEsRSS
GHSA-rf68-8gjr-36q7LowNezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty
Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty
CVE-2026-62283Critical· 9.9Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 through 1.14.14 and 2.0.0 through 2.0.9 do not bind stream identifiers created by CreateStream in service/rpc/io_strea…
GHSA-q6xx-5vr8-p898Critical· 9.9Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check
Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check
CVE-2026-53520Medium· 6.5Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing
Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing
CVE-2026-53521Medium· 6.4Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context
Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context
CVE-2026-53519Critical· 9.1PoCNezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key
Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key
CVE-2026-53522Medium· 6.5Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS
Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS
CVE-2026-53523Medium· 6.8Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection
Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection
GHSA-ww5p-j6cj-6mqqMediumNezha Dashboard: DDNS and Notification credential exposure via unredacted list API
Nezha Dashboard: DDNS and Notification credential exposure via unredacted list API
CVE-2026-49396High· 7.1Nezha has cross-site GET request that can trigger stored cron commands on a victim's agents
Nezha has cross-site GET request that can trigger stored cron commands on a victim's agents
CVE-2026-49397Medium· 5.3Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data
Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data
CVE-2026-48119High· 7.1Nezha's authenticated agents can forge service-monitor results for other users' services
Nezha's authenticated agents can forge service-monitor results for other users' services